Detection Sigma · AgentSecOps/SecOpsAgentKit

Write and convert Sigma SIEM detection rules

Creates and validates Sigma-format detection rules for SIEM platforms, converts them between backends such as Splunk, Elastic, and Sentinel, and maps detections to MITRE ATT&CK for threat hunting and compliance monitoring.

Good for

  • Draft a Sigma rule for a new detection use case
  • Convert a Sigma rule to Splunk or Elastic syntax
  • Map existing detections to MITRE ATT&CK techniques
Category
Coding

Open-source skills are maintained by their authors and listed as published, with attribution. Results depend on how well the skill fits your task and material.

A good place to start

Write a Sigma rule that detects suspicious PowerShell execution with encoded commands, and convert it to Splunk syntax.

Make your next great thing.

Bring a question, a file, or an idea that’s not quite there yet.